Executive Summary

Summary
Titlelibtasn1-3 security update
Informations
NameDSA-2440First vendor Publication2012-03-24
VendorDebianLast vendor Modification2012-03-24
Severity (Vendor) N/ARevision1

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Cvss Base Score5Attack RangeNetwork
Cvss Impact Score2.9Attack ComplexityLow
Cvss Expoit Score10AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Matthew Hall discovered that many callers of the asn1_get_length_der function did not check the result against the overall buffer length before processing it further. This could result in out-of-bounds memory accesses and application crashes. Applications using GNUTLS are exposed to this issue.

For the stable distribution (squeeze), this problem has been fixed in version 2.7-1+squeeze+1.

For the unstable distribution (sid), this problem has been fixed in version 2.12-1.

We recommend that you upgrade your libtasn1-3 packages.

Original Source

Url : http://www.debian.org/security/2012/dsa-2440

CWE : Common Weakness Enumeration

idName
CWE-189Numeric Errors

CPE : Common Platform Enumeration

TypeDescriptionCount
Application167
Application54